Privacy Policy
How VirtualBackroom.ai collects, uses, and protects your information
Last updated: June 2026
DRAFT — Pending Legal Review
This document is a working draft provided for transparency during our
pre-release prototype. It has not been reviewed or approved by
legal counsel and does not yet constitute a binding privacy notice.
Sections marked [ ] require confirmation. Please review with qualified
counsel (and applicable GDPR/CCPA requirements) before relying on or publishing
this policy.
Who We Are
VirtualBackroom.ai is operated by Koala Tea with Neel LLC (doing business as Koalat.ai). We act as the data controller for the account and service data described in this policy (such as your name, email, organization, billing, and usage records). For content you submit into the Service for analysis, we generally act as a processor on your behalf; business customers' processing of that content is governed by our Data Processing Agreement. In short: we are the controller of your account and service data, and a processor of the regulatory content you submit for analysis.
Koala Tea with Neel LLC (dba Koalat.ai)
2520 Wolfe Drive, Woodridge, IL 60517, United States
Privacy contact: neel@qms.coach
1. Information We Collect
| Category | Examples |
|---|---|
| Account data | Name, email, organization, authentication identifiers |
| Content you submit | Documents, assessment inputs, and prompts you provide for analysis |
| Usage data | Feature usage, AI-scan counts, timestamps, and audit-trail records |
| Billing data | Subscription tier and status (payment details handled by Stripe) |
| Technical data | IP address, browser type, and log/diagnostic information |
2. How We Use Your Information
- To provide, operate, and improve the Service and its AI features.
- To authenticate you and maintain account security.
- To process subscriptions and billing through our payment processor.
- To maintain ALCOA+ audit trails for compliance traceability of AI output.
- To enforce usage limits (such as monthly AI-scan allowances) and prevent abuse.
- To send service-related and, where permitted, product-update communications.
3. AI Processing & Data Handling
Before any prompt is sent to an AI model, we apply automated PII/PHI sanitization to strip personal and health identifiers from the text where applicable.
For AI features routed through OpenRouter (the bulk of our text generation), prompts are processed through OpenRouter, which does not train its own models and does not store prompt or response content (it keeps only request metadata such as token counts). Every OpenRouter-routed request is configured to route only to model providers that do not use your data to train models and do not collect it for that purpose.
A small number of features (voice transcription and text-to-speech, and certain fallback paths) call OpenAI or Google APIs directly. For these, your data is handled under those providers' API terms — which do not use data submitted via their APIs to train their models — rather than under the OpenRouter routing controls described above. Providers may temporarily retain data for abuse monitoring per their own policies.
We do not sell prompt content, and we do not use customer prompts to train models. For full detail on providers and protections, see our Security & Privacy page and our AI Boundaries page.
5. Retention & Security
- We retain account and content data while your account is active. When you close your account, we erase your personal identifiers immediately and apply the retention windows below.
- Personal data (closed accounts): identifiers are scrubbed at closure; any residual account record is retained no longer than 90 days.
- Content you submitted (e.g., documents): deleted within 30 days of account closure, unless still required for a record we must retain.
- Compliance AI audit-trail records: retained for 24 months to support regulatory traceability, then purged.
- Billing records: retained for approximately 7 years to meet tax and accounting obligations (held by our payment processor).
- Technical/operational logs: typically retained 30–90 days.
- Data is encrypted in transit (TLS 1.2+) and stored on secure infrastructure with encrypted credentials.
- We apply access controls, authentication, and abuse monitoring to protect your data.
6. Your Rights & Choices
Depending on your jurisdiction (e.g., GDPR, CCPA), you may have rights to:
- Access, correct, or delete your personal data.
- Export your data for your records or auditing purposes.
- Object to or restrict certain processing, and withdraw consent where applicable.
- Lodge a complaint with a supervisory authority.
Signed-in users can export a portable copy of their data and delete their account (which erases personal data) directly from Account Settings.
You can also exercise these rights by contacting us at neel@qms.coach; we will respond consistent with applicable law. [ Jurisdiction-specific verification and response timelines to be confirmed with counsel. ]
8. Children & Changes to This Policy
- Children. The Service is intended for business/professional use and is not directed to children under 16.
- Changes. We may update this policy; material changes will be posted on this page with a revised "Last updated" date.
Privacy Questions?
Contact us with any questions or to exercise your privacy rights.
Koala Tea with Neel LLC (dba Koalat.ai)
2520 Wolfe Drive, Woodridge, IL 60517, United States
neel@qms.coach